Acronis Cyberthreats Update, July 2025
ID: 520587db-b2f7-5c8c-b7f2-d288165f93fb
STIX ID: report--520587db-b2f7-5c8c-b7f2-d288165f93fb
Feed Name: TRU Security by Acronis
Acronis Threat Research Unit reports attackers are using a technique called "Authenticode stuffing" to insert malicious configurations into legitimately signed ConnectWise ScreenConnect installers (and similarly tampered SonicWall NetExtender installers), preserving digital signatures while redirecting installs to attacker-controlled servers to deliver backdoors and steal credentials; the report also notes a rise in malware detections in June and recommends inspecting configuration data inside signed binaries, restricting remote access tool usage, and applying multilayered protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
